Specific network equipment discovery method based on network segment scanning and customization characteristics

By modifying feature information on the existing ports of the network device to return specific features in network segment scanning, the problem that traditional methods are difficult to identify specific operating system devices is solved, and the effect of rapid and accurate identification and security improvement is achieved.

CN120075186APending Publication Date: 2025-05-30CASICLOUD-TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510244238.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Traditional network device discovery methods are difficult to quickly and accurately identify devices with specific customized operating systems, and require additional system ports to be opened, which cannot fully meet all situations.

Method used

Using a network segment scanning method, by modifying the feature information of the server's existing ports, it returns specific features to the scanner without opening the additional ports, thereby quickly identifying the target device.

Benefits of technology

It realizes the ability to quickly and accurately identify specific network devices without adding external ports, avoiding security issues and port occupancy issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075186A_ABST
    Figure CN120075186A_ABST
Patent Text Reader

Abstract

The invention discloses a specific network equipment discovering method based on network segment scanning and customization characteristics, belongs to the technical field of network management, and aims to provide a specific network equipment discovering method based on network segment scanning and customization characteristics under the condition of not additionally opening a port in a customization system by modifying the existing port characteristics of a server. And specific features are returned to the scanners by using the opened ports of the existing service, so that the scanners can conveniently discriminate the required equipment in the network. According to the method, the banner information after the connection is established is directly modified, and whether the target equipment is specific equipment or not can be simply and efficiently identified. The concurrence and flexibility characteristics of the scanning tool can be normally utilized, rapid and accurate identification can be realized, and the target equipment does not need to open an additional port.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network management, and particularly relates to a method for discovering specific network devices based on network segment scanning and customized features. Background Art

[0002] Traditional network device discovery methods mainly detect by directly sending ICMP packets to target IPs in the network or scanning a certain port, etc., for discovering devices with open relevant ports in the network. In this way, as long as the device can correctly reply to the ICMP packet or the port is in the UP state, it will be discovered by this method. There is a problem in the above process: that is, how to quickly identify which are the devices needed currently. For example: it is necessary to identify devices installed with a specific customized operating system. Traditional solutions in this regard include: 1. Guessing by using the returned ICMP packets. It is necessary to pre-save the characteristics of ICMP reply packets of various operating systems and then make a guess, and it is not necessarily possible to make an accurate judgment. 2. The target device opens a port with specific characteristics, and scanning this port with specific characteristics can achieve the purpose. This method can indeed accurately find the required system, but it needs to additionally open system ports and still cannot fully meet all situations. Summary of the Invention

[0003] (I) Object of the Invention

[0004] The object of the present invention is to design a method for discovering specific network devices based on network segment scanning. Adopting a new idea, in the customized system, by modifying the existing port characteristics of the server, without additionally opening ports. Utilize the ports already opened by the existing services to return specific characteristics to the scanner, so as to facilitate the scanner to identify the devices it needs in the network.

[0005] (II) Technical Solution

[0006] To achieve the above object, the technical solution of the present invention is as follows:

[0007] A method for discovering specific network devices based on network segment scanning and customized features, comprising the following steps:

[0008] Step 1: Use a scanning tool to scan a specific network segment, set scanning parameters according to the actual network situation and requirements, and use socket technology to connect to a specific port of the scanned end;

[0009] Step 2: Process the returned result after the specific port being scanned, specifically divided into the following two situations:

[0010] 2.1 When the specific port itself has a banner, adjust the value of the banner so that the returned value has special features related to the product;

[0011] 2.2 When a specific port does not have a banner, use a reverse proxy device to take over the specific port, intercept the scan request, return data with special characteristics, and release other requests to the original service, so as to achieve no new external ports and quickly scan out specific devices;

[0012] Step 3: The scanning end analyzes the special feature values ​​returned by the scanned end to obtain a list of devices that meet the requirements.

[0013] Furthermore, the scanning parameters include: network segment size, network latency, network bandwidth, and server configuration.

[0014] Furthermore, the specific port is SSH port 21, 22, or port 30080 of a special service.

[0015] Furthermore, the product-related feature is the product name or product version number.

[0016] Furthermore, the scanning tool is a nmap tool.

[0017] (III) Effective income

[0018] The present invention takes the nmap scanning tool connecting to the SSH service as an example. The present invention directly modifies the banner information after the connection is established (the version number of the SSH service is returned by default). By adjusting the version number to a specific version number, it is very simple and efficient to identify whether the target device is a specific device. It can normally utilize the concurrency and flexibility of nmap, and can quickly and accurately identify, and does not require the target device to open additional ports. It takes a total of 0.5 seconds to scan 256 IP addresses (including 35 normal UP hosts) through actual measurement. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 Schematic diagram of the implementation principle of the present invention. DETAILED DESCRIPTION

[0020] The present invention will be further explained and illustrated below in conjunction with the accompanying drawings and embodiments.

[0021] The present invention implements a specific network device discovery method based on network segment scanning, such as Figure 1 As shown, its implementation is mainly divided into two parts:

[0022] Part 1: The scan initiator uses a specific script to perform the scan operation and uses socket technology to connect to the specific port of the other end. When establishing the connection, it can request the scanned party to return features, or analyze and process the returned banner information to filter out the target device.

[0023] Part II: The scanned end customizes specific public services by using a specific gateway, reverse proxy, or directly adjusting the banner, and returns its own features in various forms.

[0024] The specific implementation process includes the following steps:

[0025] Step 1: Use a scanning tool (such as the nmap tool) to scan a specific network segment. The scanning parameters (such as network segment size, network latency, network bandwidth, server configuration) can be set according to the specific network situation and requirements. Use the socket technology to connect to a specific port of the scanned end (such as SSH ports 21, 22, or the port 30080 of a certain special service).

[0026] Step 2: Special processing of the scanned port. This port is not limited to newly developing a service and opening it, but allows it to be a port of an existing service (this is also the difference from the industry's common practice). Special processing is performed on the return result after the port is scanned, which is divided into two cases:

[0027] 2.1 When the port itself has a banner, adjust the value of the banner so that the returned value has special features (such as product name, product version number).

[0028] 2.2 When the port itself does not have a banner, use a reverse proxy device to take over this port, intercept the scanning request, and return data with special features (such as product name, product version number). Other requests are released to the original service. In this way, the purpose of quickly scanning specific devices can be achieved without adding new external ports.

[0029] Step 3: The scanning end analyzes the feature values returned by the scanned end to obtain a list of devices that meet the requirements, achieving the purpose.

[0030] The present invention proposes that the scanned party uses the original external port and returns the feature information to the scanning initiator by adjusting the feature information, so as to identify specific network devices. The disadvantage is that in specific cases, it may interfere with the functions of the original service or affect the service efficiency. The advantage is that there is no need to open new ports for the original network devices, avoiding some security problems and port occupation problems.

[0031] Embodiment 1

[0032] Illustrate the overall main process by way of example:

[0033] For services with a banner (such as SSH service, port 22 is open):

[0034] 1. The scanning initiator uses the socket technology to establish a connection to port 22 of the target IP.

[0035] 2. After the connection is established, the scanned end will send information to the scanning initiator. This information is the banner. The scanned end needs to customize this message to facilitate screening by the scanning end.

[0036] 3. The scanning initiator analyzes the information returned by the other party and selects devices with specific information as target devices.

[0037] For services without banners (such as HTTP services), you can use a reverse proxy to return specific information on the reverse proxy side.

[0038] 1. The scanning initiator establishes a socket connection, and the other end is a reverse proxy service

[0039] 2. After the connection is established, the reverse proxy service on the scanned end forwards normal requests to the original service for processing and return, but for specific requests, it quickly returns the characteristic values.

[0040] 3. The scan initiator initiates a specific request, and the scanned end quickly returns the characteristic value in the reverse proxy service.

[0041] 4. The scanning initiator analyzes the information returned by the other party and selects devices with specific information as target devices.

[0042] The above contents are further detailed descriptions of the present invention in combination with specific implementation methods, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the protection scope of the present invention.

Claims

1. A method for discovering specific network devices based on network segment scanning and customized features, characterized in that: The steps include: Step 1: Use the scanning tool to scan a specific network segment, set the scanning parameters according to the actual network situation and requirements, and use socket technology to connect to the specific port of the scanned end; Step 2: Process the returned results after scanning the specific port, which can be divided into the following two cases: 2.1 When a specific port itself has a banner, adjust the value of the banner so that the value returned has special characteristics related to the product; 2.2 When a specific port does not have a banner, use a reverse proxy device to take over the specific port, intercept the scan request, return data with special characteristics, and release other requests to the original service, so as to achieve no new external ports and quickly scan out specific devices; Step 3: The scanning end analyzes the special feature values ​​returned by the scanned end to obtain a list of devices that meet the requirements.

2. According to claim 1, a method for discovering specific network devices based on network segment scanning and customized features is characterized in that: The scanning parameters include: network segment size, network delay, network bandwidth, and server configuration.

3. According to claim 1, a method for discovering a specific network device based on network segment scanning and customized features is characterized in that: The specific port is SSH port 21, 22, or port 30080 of a special service.

4. According to claim 1, a method for discovering a specific network device based on network segment scanning and customized features is characterized in that: The product-related feature is the product name or product version number.

5. According to claim 1, a method for discovering specific network devices based on network segment scanning and customized features is characterized in that: The scanning tool is the nmap tool.